ELTON

ELTON's leadership and credibility in medical device cybersecurity

Credibility in medical device cybersecurity cannot be claimed. It accumulates, one device and one submission at a time, and it shows up under pressure: in an audit, in an Additional Information response, in the moment a reviewer asks how you know. So when people ask what makes ELTON different, I do not start with the software. I start with where it came from.

A decade on real devices

Our team has spent over a decade doing offensive security work on medical devices: implantables, diagnostic imaging systems, in-vitro diagnostics, remote monitoring platforms. More than 2,000 device tests across embedded hardware, wireless, mobile applications, cloud ecosystems, and the regulated data systems around them. That kind of repetition changes how you see products. You stop being surprised by scanner output and start recognizing which findings will actually matter on this particular architecture.

The regulatory side ran in parallel: more than 600 regulatory submissions supported with testing and vulnerability documentation. Watching what reviewers accept, question, and push back on across hundreds of submissions is its own education, and it is not one you can shortcut.

Where the platform comes from The ELTON platform the method, encoded in software Public work: JSP2 authorship, Black Hat 2025, published research 1,000+ FDA submissions supported 10,000+ device tests: embedded, wireless, mobile, cloud over a decade of hands-on medical device penetration testing
The software sits on top of the practice, not the other way around.

Work done in the open

Methods only get better when they are published and argued over, so we do our arguing in public. We authored the verification and validation testing section of the Health Sector Coordinating Council's Joint Security Plan 2, which sets shared expectations for how manufacturers conduct and document security testing. We presented our approach to architecture-aware vulnerability management on the Black Hat 2025 innovation track. And our research exposed a hidden backdoor in fielded patient monitors, work that fed a CISA advisory and a round of hard questions across the industry about how embedded software gets validated.

Manufacturers rarely find us through advertising. They hear about the work from peers, including members of H-ISAC, which is exactly how trust should travel in this field.

Methods regulators recognize

Every engagement follows a disciplined, standards-based approach derived from PTES and ISSAF, and it starts with threat modeling rather than a port scan. Our analysts chain low-severity findings together, exploit logic flaws, and model real attacker behavior, because realistic exploitability and patient impact are the questions that decide everything downstream. A finding that cannot be reached is a very different object from one that anchors an attack path, and the analysis has to tell them apart.

Scoring is anchored to FDA's own instruments. ELTON applies the CVSS rubric recognized under the Medical Device Development Tool program (MDDT Q171974), which means severity conclusions arrive in a methodology reviewers already know how to evaluate. That is a quieter kind of credibility than a logo wall, and it is worth more.

Why heritage matters right now

The last two years produced a wave of security tools with impressive demos and no history in front of a regulator. ELTON is the opposite construction. The platform encodes how our practitioners have actually worked for over a decade: the twin they build, the exploitability questions they ask, the documentation reviewers have accepted across 1,000+ FDA submissions. Software made the method scale. The method came first.

That ordering matters because our customers do not get to be wrong quietly. A bad severity call on a fielded device becomes a patient safety conversation, a recall conversation, or both. We designed for defensibility before we designed for convenience, and I would make that trade again.

Trust in this industry is slow to earn and quick to lose, which is exactly how it should be when patients sit at the other end of the device. We put our decade on the table with every engagement. I would be suspicious of anyone selling defensibility without one.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about credibility in medical device cybersecurity.

How do you judge a medical device security provider's experience?

By work on real devices and time in front of regulators. This team spent over a decade on offensive security across implantables, diagnostic imaging systems, in-vitro diagnostics and remote monitoring platforms, with more than 2,000 device tests and more than 600 regulatory submissions supported with testing and vulnerability documentation.

Why does published research matter in this field?

Methods only get better when they are published and argued over. This team authored the verification and validation testing section of the Health Sector Coordinating Council's Joint Security Plan 2, presented architecture-aware vulnerability management on the Black Hat 2025 innovation track, and exposed a hidden backdoor in fielded patient monitors that fed a CISA advisory.

What does a rigorous device testing method look like?

It starts with threat modeling rather than a port scan, follows a standards-based approach derived from PTES and ISSAF, and chains low-severity findings together to model real attacker behavior. A finding that cannot be reached is a very different object from one that anchors an attack path, and the analysis has to tell them apart.

Why does heritage matter when choosing a security platform?

The last two years produced security tools with impressive demos and no history in front of a regulator. The alternative is software that encodes how practitioners already worked: the model they build, the exploitability questions they ask, the documentation reviewers accepted. Software made the method scale. The method came first.

How do manufacturers usually find this kind of provider?

Through peers rather than advertising, including members of H-ISAC. Trust in medical device cybersecurity is slow to earn and quick to lose, which is how it should be when a bad severity call on a fielded device becomes a patient safety conversation, a recall conversation, or both.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON